cbcvebase.
CVE-2020-5858
published 2020-03-27

CVE-2020-5858: On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with…

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute arbitrary commands with elevated privilege via a crafted tmsh command.

Affected

82 ranges· showing 25
VendorProductVersion rangeFixed in
f5big-ip_aam
f5big-ip_access_policy_manager11.5.2 – 11.6.5
f5big-ip_access_policy_manager12.1.0 – 12.1.5
f5big-ip_access_policy_manager13.1.0 – 13.1.3
f5big-ip_access_policy_manager14.1.0 – 14.1.2
f5big-ip_access_policy_manager15.0.0 – 15.0.1
f5big-ip_advanced_firewall_manager11.5.2 – 11.6.5
f5big-ip_advanced_firewall_manager12.1.0 – 12.1.5
f5big-ip_advanced_firewall_manager13.1.0 – 13.1.3
f5big-ip_advanced_firewall_manager14.1.0 – 14.1.2
f5big-ip_advanced_firewall_manager15.0.0 – 15.0.1
f5big-ip_afm
f5big-ip_analytics
f5big-ip_analytics11.5.2 – 11.6.5
f5big-ip_analytics12.1.0 – 12.1.5
f5big-ip_analytics13.1.0 – 13.1.3
f5big-ip_analytics14.1.0 – 14.1.2
f5big-ip_analytics15.0.0 – 15.0.1
f5big-ip_apm
f5big-ip_application_acceleration_manager11.5.2 – 11.6.5
f5big-ip_application_acceleration_manager12.1.0 – 12.1.5
f5big-ip_application_acceleration_manager13.1.0 – 13.1.3
f5big-ip_application_acceleration_manager14.1.0 – 14.1.2
f5big-ip_application_acceleration_manager15.0.0 – 15.0.1
f5big-ip_application_security_manager11.5.2 – 11.6.5